If passwords are fetched remotely on-demand, you steal the account API key from memory.
If they're encrypted, you steal the master password or decryption key.
... So what's your solution?
This at the same time super cool and really disappointing, as I've been carrying around this idea in my head for maybe ten years as a cool side project and never got around to implementing it.
However, there might still be room for competition, heh. I always wanted to do this on the _entirety_ of Unicode to try getting the most possible resolution out of the image.
[0] https://spectreattack.com/
reply